Courseiva
Security Operations →easyMultiple Choice

ISC2 CC Security Operations Practice Question

An organization wants to ensure that only authorized devices can connect to its corporate Wi-Fi network. The security team decides to implement a solution that requires devices to authenticate before being granted network access. Which technology should they use?

⚠ Common exam trap

Many candidates confuse WPA3-SAE, which is a strong encryption protocol, with network access control; it still uses a shared password and does not authenticate individual devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

802.1X with a RADIUS server

802.1X with a RADIUS server provides port-based network access control, requiring each device to authenticate before being granted access. It supports various authentication methods such as certificates or credentials, making it ideal for ensuring only authorized devices connect to corporate Wi-Fi. Other options like pre-shared keys or MAC filtering are weaker and not scalable for enterprise use.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MAC address filtering

    Why it's wrong here

    MAC address filtering allows or denies devices based on their hardware address, but MAC addresses can be spoofed easily. It does not provide strong authentication and is difficult to manage in large environments. It is not a robust solution for ensuring only authorized devices connect.

  • ✗

    WPA3-SAE with a shared password

    Why it's wrong here

    WPA3-SAE improves security over WPA2-Personal by using Simultaneous Authentication of Equals, but it still relies on a shared password. It does not provide individual device authentication or integration with directory services. For corporate environments needing per-device authorization, 802.1X is more suitable.

  • ✗

    WPA2-Personal with a pre-shared key

    Why it's wrong here

    WPA2-Personal uses a pre-shared key that is shared among all users. It does not provide per-device authentication or prevent unauthorized devices if the key is known. It is suitable for home networks but lacks the granular access control needed for corporate environments where only authorized devices should connect.

  • ✓

    802.1X with a RADIUS server

    Why this is correct

    802.1X is an IEEE standard for port-based network access control that requires devices to authenticate via a RADIUS server before gaining network access. It supports per-device credentials, certificates, or other methods, ensuring only authorized devices connect. This is the appropriate solution for corporate Wi-Fi networks requiring strong authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.